imtoken[.]down-zh-cn[.]com
Verifica phishing e sicurezza per imtoken.down-zh-cn.com
“imToken | Ethereum & Bitcoin Wallet”
imtoken.down-zh-cn.com — Contenuto non disponibile (HTTP 502). Simulazione del marchio: Across; Tipo di truffa: Crypto Scam. Riepilogo delle prove: VT 10/91 (BitDefender, Chong Lua Dao, CyRadar, ESET, Fortinet); URLQuery 4 alerts; URLScan no malicious verdict; GSB no flag; BL 0; PD 84/100. Registrar: Gname.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
imtoken.down-zh-cn.com is a subdomain of down-zh-cn.com. PhishDestroy first observed the hostname on Feb 3, 2026. Stored content metadata identifies Across as the apparent target. The captured page title is “imToken | Ethereum & Bitcoin Wallet”. Page analysis recorded additional brand references to Discord, Ethereum, and Ton. Stored page analysis classifies the content as crypto scam. Current evidence score: 84/100 (critical).
Positive findings are stored from 2 sources: VirusTotal and URLQuery. VirusTotal recorded 10 detections among 91 engines: BitDefender, Chong Lua Dao, CyRadar, ESET, Fortinet, G-Data, Gridinsoft, Lionic, Sophos, Webroot on Aug 1, 2026 at 02:31 UTC. URLQuery recorded 4 threat-system alerts on Feb 3, 2026 at 21:55 UTC. Non-positive and contextual checks: The external blocklist snapshot contained no matches on Aug 7, 2026 at 18:20 UTC. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. URLScan completed without a malicious verdict on Jul 29, 2026 at 03:26 UTC. PhishStats returned no feed match on Mar 2, 2026 at 00:02 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 02:02 UTC; content was unavailable. Registration records for the registrable domain down-zh-cn.com list Gname.com Pte. Ltd. as the registrar. At collection time, the hostname resolved to 18.162.53.8 on AS16509 (AMAZON-02 - Amazon.com, Inc., US). The IP and ASN identify shared CDN edge infrastructure; the origin server is not established by this address. The stored server header is nginx. DOM analysis on Apr 23, 2026 at 03:22 UTC returned 10/100. The evidence archive retains 3 visual captures from PhishDestroy, URLScan, and URLQuery.
The content indicators and 2 positive source findings support the current Across-themed crypto scam classification.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | imtoken.down-zh-cn.com |
malicious | Sinkholed |
| OpenDNS | imtoken.down-zh-cn.com |
phishing | Phishing Block |
| Quad9 DNS | imtoken.down-zh-cn.com |
malicious | Sinkholed |
| DNS4EU | imtoken.down-zh-cn.com |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Registration: down-zh-cn.com
Accreditamento e contesto RAA
Accreditamento e contesto RAA
ICANN ha incassato. La responsabilità non è arrivata.
For the registrable domain down-zh-cn.com behind this subdomain, the registrar above operates under an ICANN contract. ICANN collects annual, variable and transaction-based fees tied to registrations, renewals and transfers.
Accreditamento: monetizzato. Responsabilità: ricontrollare più tardi.
Poi inizia la magia: ICANN scrive il RAA §3.18, il registrar indaga sugli abusi all’interno della propria base clienti e le vittime forniscono gratuitamente le prove, mentre ogni livello aspetta che agisca qualcun altro. Se questo fa sentire le vittime più al sicuro, eccellente — la fattura ha funzionato.
Analisi di VirusTotal
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo